Lab Setup & Prerequisites
Complete these steps before starting Lab 1. You will access your lab VM, log into both Zscaler tenants, configure the Zscaler Client Connector forwarding profile, and verify notifications are enabled. Allow 15 minutes.
All access details โ Skytap VM link, tenant usernames, and passwords โ were sent to you by the Zscaler Training Team before the session. Keep that email open throughout the lab.
Lab Environment Overviewโ
Your lab environment consists of two components:

| Component | Description |
|---|---|
| Corp Client PC | A Windows VM hosted in Skytap. Used for all Kevin (end user) tasks in Labs 6, 7, and 8. |
| Admin Portal | The Zscaler console accessed from your own laptop. Used for all Alex and Priya tasks. |
| Zscaler Cloud | Your traffic and DLP enforcement plane. ZCC on the VM routes all traffic through Zscaler. |
Part 1 โ Access Your Lab Environmentโ
Step 1 โ Check Your Emailโ
Look for an email from Zscaler Training Team with subject Data Security (EDU-220) - Instructor Led Training.

The email contains:
- Skytap URL โ unique link to your lab VM (no password required)
- ZIdentity Landing Page โ for Lab Tenant access
- Student Admin Username โ
student@zs000XXX.labtenant.com - One Time Password โ you will be prompted to change this on first login
- SDC Credentials โ for Enterprise Tenant access
Step 2 โ Access the Lab VMโ
Click your Skytap URL from the email. The Windows VM launches automatically โ no username or password required.

Verify the VM is ready:
- Zscaler Client Connector icon visible in the system tray
- File
Dataparity_Q2_2025_Workforce_Financial_Summary.docxis on the Desktop
Step 3 โ Log Into the Enterprise Tenant (Modules 1 & 3)โ
From your laptop browser, navigate to https://sdc.zslogin.net/ and log in with your SDC Admin credentials from the email.

| Field | Value |
|---|---|
| Login URL | https://sdc.zslogin.net/ |
| Admin Username | ca-XXXX-ADMIN@thezerotrustexchange.com |
| Password | From your email |
Step 4 โ Log Into the Lab Tenant (Module 2)โ
From your laptop browser, navigate to your ZIdentity Landing Page from the email (format: zs000XXX.zslogin.net) and log in with your Student Admin credentials. You will be prompted to set a new password on first login.
| Tenant | Used In | Access | Login URL |
|---|---|---|---|
| Enterprise Tenant (SDC) | Modules 1 + 3 | Read-Only | sdc.zslogin.net |
| Lab Tenant | Module 2 only | Read/Write | Your ZIdentity URL from email |
The facilitator will indicate when to switch tenants at the start of each module.
Part 2 โ Configure Zscaler Client Connector (Lab Tenant)โ
These steps configure the Client Connector forwarding profile and app policy on the lab VM. This is required for Labs 6, 7, and 8 to enforce DLP policies on endpoint traffic.
All steps in Part 2 are performed in the Lab Tenant using the ZIdentity Client Connector tile. Make sure you are logged into the Lab Tenant before proceeding.
Step 5 โ Log Into ZIdentity and Open Client Connectorโ
On the Corp Client PC (VM), open Chrome and navigate to your ZIdentity Landing Page. Log in with your Student Admin credentials, then click the Zscaler Client Connector tile.

Step 6 โ Navigate to Forwarding Profileโ
Navigate to:

Step 7 โ Add Forwarding Profileโ
Click Add Forwarding Profile and configure:
- Name:
HandsOnLab_FW_Profile - Windows Driver Selection: Packet Filter Based

Step 8 โ Configure ZIA Tunnel Settingsโ
In the FORWARDING PROFILE ACTION FOR ZIA section:
- On-Trusted Network: Tunnel
- Tunnel version: Z-Tunnel 2.0

Step 9 โ Configure System Proxy Settingsโ
Scroll down and expand Configure System Proxy Settings:
- Configure System Proxy Settings: Enforce
- Ensure all options are unchecked

Step 10 โ Configure VPN and Off-Trusted Networkโ
- VPN Trusted Network: Check Same as "On-Trusted Network"
- Off Trusted Network: Check Same as "On-Trusted Network"

Step 11 โ Configure ZPA Forwarding Profileโ
In the FORWARDING PROFILE ACTION FOR ZPA section:
- On-Trusted Network: Tunnel
- VPN-Trusted Network: Same as "On-Trusted Network"
- Off-Trusted Network: Same as "On-Trusted Network"
Click Save.

Step 12 โ Navigate to App Profilesโ
Navigate to:

Step 13 โ Add Windows App Policyโ
Click Add Windows Policy and configure:
- Name:
HandsOnLab_App_Profile - Rule Order: 1
- Status: Enable
- Forwarding Profile:
HandsOnLab_FW_Profile - Install Zscaler SSL Certificate: On
- User Groups: Select All โ Done

Step 14 โ Enable Data Protection / Endpoint DLPโ
In the same Windows App Policy:
- Data Protection: Install Endpoint ZDP
- Expand Notification and Logging:
- Use Zscaler Notification Framework: Enable
- Bring Notification to Focus: Enable
Click Add.

Step 15 โ Enable Client Connector Notificationsโ
Navigate to:
You can either edit the existing Legacy Notification Settings template (click the edit icon) or create a new template using the + Add Notification Template button. Either approach works โ just ensure the template is saved and active before proceeding.
Click the edit icon next to Legacy Notification Settings.

Configure the following settings in the Edit Notification Template dialog:
| Setting | Value |
|---|---|
| Show ZCC Notification Popups by Default | Enabled |
| Enable Service Status Notifications | Enabled |
| Enable ZIA Notifications | Enabled |
| Enable Persistent Notifications | Enabled |
| Enable Notifications for ZPA Reauthentication | Enabled |
| Custom Timer (In Seconds) | 5 |
Click Save.

Steps 5โ15 configure the forwarding profile and enable endpoint DLP notifications. This is required before Labs 6, 7, and 8 โ without these steps, the ZCC block notifications will not appear on screen when Kevin's actions are blocked. Allow 5โ7 minutes for all students to complete these steps.
Part 3 โ Navigate to Experience Center (Module 2)โ
For all Module 2 configuration tasks (Labs 5, 6, and 7), Alex uses the Experience Center โ Zscaler's unified console โ rather than the standard admin portal.
After logging into the Lab Tenant, click Experience Center in the banner at the top of the ZIdentity page.

Callout โ Click Experience Center in the blue banner at the top
The Experience Center provides a unified view of all Zscaler products and is the primary console for configuring DLP policies, engines, and resources in Labs 5, 6, and 7.
Part 4 โ Setup VM and Login to Zscaler Client Connector (ZCC)โ
Step 1 โ Login to the VMโ
Locate the Skytap URL in your lab access email and click it. The Windows VM launches automatically โ no username or password required.
If you log off or need to log back in manually, use username: student / password: Admin-123!

Step 2 โ Open and Login to Zscaler Client Connectorโ
Locate the ZCC icon in the system tray (bottom right of the taskbar) โ , right-click it, and select Open Zscaler โก. The Zscaler Client Connector window opens โข.
Use your Lab Tenant credentials to log in โ the same username and password you set up in Part 3.
Use your updated password, not the one-time password from the email. ZIdentity prompted you to change it on first login โ use that new password here.

Tip โ Copy/Paste from your local machine to the VM:
Use the VM Clipboard tool in the SkyTap toolbar at the top of the VM window โ . Paste your credential into the clipboard field, then paste inside the VM using Ctrl+V. This works in both directions โ local to VM and VM to local โก.

Step 3 โ Verify All Modules Are Activeโ
Once logged in, the ZCC dashboard opens. Confirm the following:
- Authentication Status: Authenticated (green)
- Service Status: ON
- All modules (Private Access, Internet Security, Digital Experience, Data Protection) are visible and active

Step 4 โ Verify Traffic Is Being Steered to Zscalerโ
Open a browser inside the VM and navigate to https://ip.zscaler.com. The page should confirm your traffic is passing through the Zscaler Zero Trust Exchange and display your Zscaler proxy details.

Notepad++ is pre-installed on the VM โ no installation needed. It is ready to use for Lab 7.
Quick Reference โ All Credentialsโ
| What | URL | Username | Password |
|---|---|---|---|
| Enterprise Tenant (Admin) | https://sdc.zslogin.net/ | ca-XXXX-ADMIN@thezerotrustexchange.com | From email |
| Lab Tenant | ZIdentity URL from email | student@zs000XXX.labtenant.com | One Time Password from email |
| Browser DLP Extension (Lab 8) | Tenant: dlpdemo | Same as Enterprise Tenant Admin | Same as Enterprise Tenant |
| Lab VM | Skytap URL from email | student | Admin-123! |
| Zscaler Client Connector (VM) | N/A | Same as Lab Tenant Admin username | Same as updated Lab Tenant password |
The ca-XXXX and zs000XXX numbers in screenshots throughout this lab guide were captured during preparation. Use the credentials from your email.
Before moving to Lab 1, do a quick show-of-hands:
- Can everyone access the Enterprise Tenant at sdc.zslogin.net? โ
- Can everyone access their Lab Tenant? โ
- Has everyone completed the forwarding profile setup? โ
- Is Zscaler Client Connector logged in and all modules active on the VM? โ
- Does ip.zscaler.com confirm traffic is tunneled through Zscaler? โ
Resolve any blockers before proceeding โ all subsequent labs depend on these steps being complete.